Published onAugust 10, 2025SEO PoisoningSEO-POISONINGSEO Poisoning is an attack designed to manipulate search engine algorithms, promoting malicious pages to appear in top positions in search results.Read more →
Published onJune 10, 2025Dynamite WriteupRace-ConditionSSTILFRGraphQLLinuxHacking-ClubThe Dynamite machine is vulnerable to Race condition, SSTI, LFR and more. Read more →
Published onMay 12, 2025HeartMatch WriteupInsecure-DesseralizationLinuxHacking-ClubThe HeartMatch machine is vulnerable to insecure desseralization and privilege escalation trough SUIDRead more →
Published onMarch 22, 2025Evasion WriteupLFILinuxHacking-ClubThe Evasion machine is vulnerable to LFI with filter bypass, session poisoning for RCE, crontab, and privilege escalation via sudo.Read more →
Published onMarch 5, 2025IAM WriteupSSRFCloudLinuxHacking-ClubIAM Machine has the CVE-2021-40438 vulnerability, which allows SSRF in Apache, resulting in temporary AWS credentials and privilege escalation to root.Read more →